Lucene search

K
cveMitreCVE-2004-1337
HistoryJan 06, 2005 - 5:00 a.m.

CVE-2004-1337

2005-01-0605:00:00
mitre
web.nvd.nist.gov
37
cve
linux kernel 2.6
posix capability
lsm
security module
local privilege escalation

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

5.5

Confidence

High

EPSS

0

Percentile

5.1%

The POSIX Capability Linux Security Module (LSM) for Linux kernel 2.6 does not properly handle the credentials of a process that is launched before the module is loaded, which allows local users to gain privileges.

Affected configurations

Nvd
Node
gnurealtime_linux_security_moduleMatch0.8.7
OR
conectivalinuxMatch10.0
Node
ubuntuubuntu_linuxMatch4.1ia64
OR
ubuntuubuntu_linuxMatch4.1ppc
VendorProductVersionCPE
gnurealtime_linux_security_module0.8.7cpe:2.3:a:gnu:realtime_linux_security_module:0.8.7:*:*:*:*:*:*:*
conectivalinux10.0cpe:2.3:o:conectiva:linux:10.0:*:*:*:*:*:*:*
ubuntuubuntu_linux4.1cpe:2.3:o:ubuntu:ubuntu_linux:4.1:*:ia64:*:*:*:*:*
ubuntuubuntu_linux4.1cpe:2.3:o:ubuntu:ubuntu_linux:4.1:*:ppc:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

5.5

Confidence

High

EPSS

0

Percentile

5.1%